First published: Mon May 13 2019(Updated: )
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iCloud for Windows 7.12, tvOS 12.3, iTunes 12.9.5 for Windows, macOS Mojave 10.14.5, Security Update 2019-003 High Sierra, Security Update 2019-003 Sierra, iOS 12.3. Processing a maliciously crafted font may result in the disclosure of process memory.
Credit: riusksk VulWar Corp working with Trend Microriusksk VulWar Corp working with Trend Microriusksk VulWar Corp working with Trend Microriusksk VulWar Corp working with Trend Micro product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iTunes for Windows | <12.9.5 | 12.9.5 |
Apple macOS Mojave | <10.14.5 | 10.14.5 |
Apple High Sierra | ||
Apple Sierra | ||
Apple tvOS | <12.3 | 12.3 |
Apple iOS | <12.3 | 12.3 |
Apple Icloud Windows | <7.12 | |
Apple Itunes Windows | <12.9.5 | |
Apple iPhone OS | <12.3 | |
Apple Mac OS X | <10.14.5 | |
Apple tvOS | <12.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2019-8582 is a vulnerability in CoreText that allows an attacker to perform an out-of-bounds read.
The severity of CVE-2019-8582 is medium, with a severity value of 5.5.
CVE-2019-8582 affects iCloud for Windows 7.12, tvOS 12.3, iTunes 12.9.5 for Windows, macOS Mojave 10.14.5, Security Update 2019-003 High Sierra, Security Update 2019-003 Sierra, and iOS 12.3.
To fix CVE-2019-8582, update to iCloud for Windows 7.12, tvOS 12.3, iTunes 12.9.5 for Windows, macOS Mojave 10.14.5, Security Update 2019-003 High Sierra, Security Update 2019-003 Sierra, or iOS 12.3.
You can find more information about CVE-2019-8582 on the Apple support website at the following links: [link1](https://support.apple.com/en-us/HT210119), [link2](https://support.apple.com/en-us/HT210118), [link3](https://support.apple.com/en-us/HT210120).